Access of Memory Location After End of Buffer in PowerEdge Server BIOS and Precision Rack BIOS - CVE-2024-0154
Published: August 1, 2024
Vulnerability identifier: #VU95135
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0154
CWE-ID: CWE-788
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to improper parameter initialization. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
Affected software
PowerEdge Server BIOS
Precision Rack BIOS
PowerFlex Appliance
APEX Cloud Platform Foundation Software
APEX Cloud Platform for Red Hat OpenShift
Precision Rack BIOS
PowerFlex Appliance
APEX Cloud Platform Foundation Software
APEX Cloud Platform for Red Hat OpenShift
How to mitigate CVE-2024-0154
Install updates from vendor's website.
PowerFlex Appliance - update to IC-46.380.01
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39